Common Criteria · Security TSC
The 9 Common Criteria categories, mandatory for every SOC 2 report. Shared with ISO 27001 Annex A and NIST CSF 2.0.
- CC1 Control Environment, board oversight, ethics, organizational structure, competence
- CC2 Communication & Information, internal control responsibilities + auditor communication
- CC3 Risk Assessment, fraud risk, change-driven reassessment, COSO ERM alignment
- CC4 Monitoring Activities, ongoing + separate evaluations, deficiency remediation
- CC5 Control Activities, policy + procedure deployment, technology general controls
- CC6 Logical & Physical Access, provisioning, MFA, encryption, physical access, malware
- CC7 System Operations, vulnerability mgmt, anomaly detection, incident response, BCM
- CC8 Change Management, authorize, design, develop, test, approve, deploy
- CC9 Risk Mitigation, business disruption, vendor + business-partner risk





